CVE-2026-0239

Chronosphere Chronocollector Information Disclosure Vulnerability

Severity
Medium 4.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.1th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto

Description

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

Weakness: CWE-497

Affected products

Vendor Product Category Matched by
Palo Alto Networks Chronosphere SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Chronosphere Chronocollector

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Suggested Solution Chronosphere Chronocollector Upgrade to v0.116.0 or later.

Something wrong here?